1. Our role, and an important note
BidLoop is a platform used by construction businesses to price, plan, run and claim their projects. It is sold to businesses, not to consumers.
Much of the Personal Information we hold is put into the platform by our customers — the names of their staff and crews, the contact details of their clients and suppliers, and the names and details that appear on invoices, quotes and drawings they upload. Where that is the case, we hold and handle that information on the customer's behalf and on their instructions. The customer is responsible for how it was collected and for its accuracy, and this Policy should be read together with that customer's own privacy policy.
The parts of this Policy about information we collect from you directly apply mainly to workspace owners and users, to people who upload a receipt through a drop link a customer has given them, to people who contact us, and to visitors to our website.
2. The kinds of Personal Information we collect
2.1 Workspace owners and users
Name, business name, job title or role, email address, phone number, the workspace you belong to and your role and approval limit within it, account credentials and security information (including multi-factor authentication settings), your signature block where you add one, and records of your activity in the platform such as what you created, approved or changed and when.
2.2 People inside customer data
Information our customers enter or upload, which we hold on their behalf. It commonly includes the names of employees and crew members, contact names and details for clients, suppliers and subcontractors, and any personal details that happen to appear in documents uploaded to the platform — invoices, receipts, quotes, rate sheets, drawings, letters and correspondence.
2.3 People who send in a document
Where a customer gives you a drop link or an intake email address to send receipts or invoices to, we collect the full name you enter, the file you send and technical information about the request (including your IP address and a device token used to keep the link usable without asking for the access code every time). This information goes to the customer whose link it is.
2.4 Website visitors and enquiries
If you ask for a demo through our website we collect your name, company, email address, and any phone number and message you provide. If you contact us by email we collect what you send us.
2.5 Billing
We do not currently take payment through the platform. Where fees are payable we hold the billing contact and transaction details needed to invoice and account for them. If we introduce a payment provider we will name it in section 8 and update this Policy; we would not store full payment card numbers ourselves.
3. How we collect Personal Information
- Directly from you — when you are invited to or set up a workspace, use the platform, ask for a demo, or contact us.
- From our customers — when they enter details or upload documents into their workspace, including by forwarding email to their intake address or sharing a drop link.
- From documents — we read the contents of documents uploaded to the platform in order to extract the details they contain (see section 6).
- From connected services — where a customer connects their accounting system, we receive data back from it (see section 7).
- From public sources — we check Australian Business Numbers against the Australian Business Register to confirm supplier and client details.
- Through your use of our website and the platform — see section 11.
If we collect Personal Information about you from someone other than you, we will take steps that are reasonable in the circumstances to make you aware of it, unless an exception under the Privacy Act applies or the collection is required or authorised by law.
4. Why we collect, use and disclose Personal Information
We use Personal Information for the purpose it was collected for, and for related purposes you would reasonably expect. Those purposes include:
- providing, operating, securing and supporting the platform, including creating workspaces, authenticating users and enforcing roles and approval limits;
- reading and coding documents you upload so they can be matched, approved and posted to the right job and cost code;
- sending service messages — approval requests, reminders, notifications and receipts;
- connecting to and exchanging data with a customer's accounting system where they have authorised it;
- maintaining audit trails of who approved or changed what, which is a core function of the product;
- metering usage against the limits that apply to a workspace;
- diagnosing faults and improving the platform's reliability and security;
- responding to enquiries, providing support and handling complaints;
- marketing our own products and services to businesses (see section 10); and
- meeting our legal obligations and protecting our lawful interests.
We may also use or disclose Personal Information where required or authorised by law, where it is necessary to lessen or prevent a serious threat to a person's life, health or safety, or where we reasonably suspect unlawful activity.
We do not sell Personal Information, and we do not disclose it to third parties for their own advertising.
5. Who we disclose Personal Information to
- The customer whose workspace the information belongs to — including, where you send in a document, the business whose drop link or intake address you used.
- Our service providers, listed in section 8.
- A connected accounting system, where the customer has authorised the connection (section 7).
- Our professional advisers, such as legal and accounting advisers, where reasonably required.
- Government agencies, regulators or law enforcement, where required or authorised by law.
- A purchaser or successor in connection with an actual or proposed sale or reorganisation of our business.
Workspaces are kept separate from one another. Our own administrative staff can see account-level information — the workspace name, its plan, its usage and its storage — in order to operate and support the service, and can access the contents of a workspace only where it is necessary to provide support, to investigate a fault or a security issue, or where the law requires it.
6. Artificial intelligence features
Several parts of the platform use artificial intelligence to read documents and suggest results. When you use one of those features, the document or image concerned is sent to our AI provider, Anthropic, to be processed, and the result is returned to your workspace. This currently applies to:
- Invoices and receipts — reading the supplier, date, reference, amounts and line items so they can be coded and approved;
- Rate sheets and price books — reading supplier pricing so it can be brought into a rate library;
- Drawings — taking measurements and chainages off long-section and plan drawings;
- Estimate review — checking an estimate for scope gaps and suggesting rate names and groupings.
Those documents can contain Personal Information — a contact name on an invoice, a signature, a name on a delivery docket. Anthropic processes that material on our instructions in order to return the result, is bound by its own terms not to use material submitted through its business API to train its models, and is located in the United States (see section 9).
AI output is a suggestion, not a decision. Everything it produces is presented for a person to review, correct and approve before it affects any figure, and the platform records who approved it.
7. Xero and other integrations
A customer can connect their Xero organisation to their workspace. Connecting is done through Xero's own authorisation screen, and the customer chooses to grant it. Once connected, we may send approved bills, credit notes and their attached documents to Xero, and read back contacts, accounts, tracking categories and the status of documents we have sent, so the two stay in step. What flows across can include supplier contact details and the contents of the documents themselves. Xero handles that information under its own terms and privacy policy. A customer can disconnect at any time from the platform's settings.
8. Our service providers
We use third parties to run the platform. We disclose Personal Information to them only to the extent needed for them to perform their service to us, and we take reasonable steps to ensure they handle it consistently with the Privacy Act.
| Provider | What it does | Where |
|---|---|---|
| Convex | Application database, file storage and backend functions | United States |
| Clerk | Sign-in, accounts and multi-factor authentication | United States |
| Railway | Application hosting and infrastructure | United States |
| Anthropic | AI document reading (section 6) | United States |
| Resend | Email delivery, and receiving invoices forwarded to an intake address | United States |
| Sentry | Error and performance monitoring | United States |
| Xero | Accounting integration, where a customer connects it (section 7) | New Zealand / Australia |
Conversion of Word and Excel documents to PDF is done by software we run ourselves on our own hosting, not by a third-party document service. We may update this list as our providers change, and will update this Policy when we do.
9. Overseas disclosure
As the table above shows, most of our infrastructure operates in the United States. This means Personal Information held in the platform may be disclosed to, stored in, or accessed from outside Australia.
Where we disclose Personal Information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles. Because these are internet services reachable from multiple locations, it is not always practicable to identify every country in which information may be held or accessed from. If you do not agree to your Personal Information being handled outside Australia, please do not submit it to us, and contact us using the details in section 18.
10. Direct marketing
We may use business contact details to tell you about our products, services and offers, by email or telephone, where you have consented or where it is within your reasonable expectation given your dealings with us. You can opt out at any time using the unsubscribe link in the message or by contacting us. We do not use sensitive information for direct marketing.
Service messages — approval requests, notifications, receipts and the like — are not marketing and are sent as part of running the platform.
11. Cookies and technical data
Our public website sets no cookies and runs no analytics or advertising scripts. The platform itself uses cookies that are necessary to keep you signed in securely; these are set by our authentication provider. If we ever introduce analytics, we will name the provider in section 8 and update this Policy.
We collect IP addresses and technical information such as browser and device details to operate, secure and troubleshoot the service. That information does not usually identify you on its own, but where we combine it with other Personal Information we hold, we treat it as Personal Information.
12. Sensitive information
Sensitive information is a subset of Personal Information — for example health, biometric, racial or ethnic information, or union membership. We do not seek to collect sensitive information, and the platform is not designed to hold it. Please do not upload documents containing it. If we do collect it, we will only do so with consent or where required or authorised by law.
Bank account details and Australian Business Numbers appearing on supplier invoices are not "sensitive information" as the Privacy Act defines it, but we treat them with the same care as the rest of the financial data in a workspace.
13. How we keep Personal Information secure
We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include encryption in transit and at rest, separation of each workspace's data with access checked on every request, role-based permissions and approval limits enforced on the server rather than only in the interface, multi-factor authentication, audit trails of significant actions, and monitoring for errors and unusual activity.
No method of transmission or storage is completely secure and we cannot guarantee absolute security, particularly where human error or malicious third-party activity is involved.
14. How long we keep Personal Information
We keep Personal Information for as long as it is needed to provide the service and for related purposes, and to meet our legal, accounting and record-keeping obligations. Because the platform holds financial records, customers commonly need their data retained for a number of years for tax and audit purposes, and we retain it for the life of the workspace on that basis.
When a workspace is closed we will, on request and for a reasonable period afterwards, make available a means for the customer to export their data. After that, we take reasonable steps to destroy or de-identify Personal Information that is no longer needed, except for copies held in routine backups or where the law requires us to retain it.
15. Access to, and correction of, your Personal Information
You may ask for access to, or correction of, the Personal Information we hold about you by contacting us using the details in section 18. We will respond within a reasonable time and may need to verify your identity first. In limited circumstances permitted by law we may decline a request, and if we do we will explain why.
If your request relates to information we hold on behalf of one of our customers — for example your details as they appear on an invoice inside their workspace — we will usually need to direct you to that business, because the records are theirs and they are responsible for them. We will help you identify who to contact where we reasonably can.
16. Data breaches
We maintain procedures to identify and respond to data breaches. If a breach involving Personal Information is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required. Where the information concerned is held on behalf of a customer, we will notify that customer promptly and work with them so they can meet their own obligations.
17. Anonymity and pseudonymity
Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym. It is usually not practicable in the platform itself: an approval trail is only meaningful if it records who actually approved something.
18. Complaints and how to contact us
If you have a question or a complaint about how we have handled your Personal Information, please contact our Privacy Officer:
BidLoop Pty Ltd (ACN 700 602 464)
Attention: Privacy Officer
Email: hello@bidloop.com.au
Postal address: Level 18, 360 Queen Street, Brisbane City QLD 4000
We will acknowledge your complaint, work with you to understand it, and aim to resolve it within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
19. Changes to this Privacy Policy
We may update this Policy from time to time to reflect changes in our practices or our legal obligations. We will publish the updated version here and change the "last updated" date above, and where a change is material we will take reasonable steps to notify you. By continuing to use the platform after an updated Policy takes effect, you acknowledge that Policy.