Privacy Policy

Last updated: 10 August 2026

BidLoop Pty Ltd (ACN 700 602 464) (BidLoop, we, us or our) respects your privacy. We handle Personal Information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), which govern how we collect, use, hold, secure and disclose Personal Information.

The short version

  • Your job data is yours. We hold it to run the service for you, and we do not sell it or use it to advertise to anyone.
  • Each workspace is separate. No customer can see another customer's estimates, rates or costs.
  • We send some of your documents to an AI provider to read them — invoices, rate sheets, drawings. That is set out in section 6.
  • Most of our infrastructure is in the United States. Section 9 says which providers and why.
  • Your invoices and contact records often contain other people's details. You are the one who collected those; we hold them for you.

This box is a plain-English summary to help you find things. It is not part of the policy and the sections below are what apply.

1. Our role, and an important note

BidLoop is a platform used by construction businesses to price, plan, run and claim their projects. It is sold to businesses, not to consumers.

Much of the Personal Information we hold is put into the platform by our customers — the names of their staff and crews, the contact details of their clients and suppliers, and the names and details that appear on invoices, quotes and drawings they upload. Where that is the case, we hold and handle that information on the customer's behalf and on their instructions. The customer is responsible for how it was collected and for its accuracy, and this Policy should be read together with that customer's own privacy policy.

The parts of this Policy about information we collect from you directly apply mainly to workspace owners and users, to people who upload a receipt through a drop link a customer has given them, to people who contact us, and to visitors to our website.

2. The kinds of Personal Information we collect

2.1 Workspace owners and users

Name, business name, job title or role, email address, phone number, the workspace you belong to and your role and approval limit within it, account credentials and security information (including multi-factor authentication settings), your signature block where you add one, and records of your activity in the platform such as what you created, approved or changed and when.

2.2 People inside customer data

Information our customers enter or upload, which we hold on their behalf. It commonly includes the names of employees and crew members, contact names and details for clients, suppliers and subcontractors, and any personal details that happen to appear in documents uploaded to the platform — invoices, receipts, quotes, rate sheets, drawings, letters and correspondence.

2.3 People who send in a document

Where a customer gives you a drop link or an intake email address to send receipts or invoices to, we collect the full name you enter, the file you send and technical information about the request (including your IP address and a device token used to keep the link usable without asking for the access code every time). This information goes to the customer whose link it is.

2.4 Website visitors and enquiries

If you ask for a demo through our website we collect your name, company, email address, and any phone number and message you provide. If you contact us by email we collect what you send us.

2.5 Billing

We do not currently take payment through the platform. Where fees are payable we hold the billing contact and transaction details needed to invoice and account for them. If we introduce a payment provider we will name it in section 8 and update this Policy; we would not store full payment card numbers ourselves.

3. How we collect Personal Information

If we collect Personal Information about you from someone other than you, we will take steps that are reasonable in the circumstances to make you aware of it, unless an exception under the Privacy Act applies or the collection is required or authorised by law.

4. Why we collect, use and disclose Personal Information

We use Personal Information for the purpose it was collected for, and for related purposes you would reasonably expect. Those purposes include:

We may also use or disclose Personal Information where required or authorised by law, where it is necessary to lessen or prevent a serious threat to a person's life, health or safety, or where we reasonably suspect unlawful activity.

We do not sell Personal Information, and we do not disclose it to third parties for their own advertising.

5. Who we disclose Personal Information to

Workspaces are kept separate from one another. Our own administrative staff can see account-level information — the workspace name, its plan, its usage and its storage — in order to operate and support the service, and can access the contents of a workspace only where it is necessary to provide support, to investigate a fault or a security issue, or where the law requires it.

6. Artificial intelligence features

Several parts of the platform use artificial intelligence to read documents and suggest results. When you use one of those features, the document or image concerned is sent to our AI provider, Anthropic, to be processed, and the result is returned to your workspace. This currently applies to:

Those documents can contain Personal Information — a contact name on an invoice, a signature, a name on a delivery docket. Anthropic processes that material on our instructions in order to return the result, is bound by its own terms not to use material submitted through its business API to train its models, and is located in the United States (see section 9).

AI output is a suggestion, not a decision. Everything it produces is presented for a person to review, correct and approve before it affects any figure, and the platform records who approved it.

7. Xero and other integrations

A customer can connect their Xero organisation to their workspace. Connecting is done through Xero's own authorisation screen, and the customer chooses to grant it. Once connected, we may send approved bills, credit notes and their attached documents to Xero, and read back contacts, accounts, tracking categories and the status of documents we have sent, so the two stay in step. What flows across can include supplier contact details and the contents of the documents themselves. Xero handles that information under its own terms and privacy policy. A customer can disconnect at any time from the platform's settings.

8. Our service providers

We use third parties to run the platform. We disclose Personal Information to them only to the extent needed for them to perform their service to us, and we take reasonable steps to ensure they handle it consistently with the Privacy Act.

ProviderWhat it doesWhere
ConvexApplication database, file storage and backend functionsUnited States
ClerkSign-in, accounts and multi-factor authenticationUnited States
RailwayApplication hosting and infrastructureUnited States
AnthropicAI document reading (section 6)United States
ResendEmail delivery, and receiving invoices forwarded to an intake addressUnited States
SentryError and performance monitoringUnited States
XeroAccounting integration, where a customer connects it (section 7)New Zealand / Australia

Conversion of Word and Excel documents to PDF is done by software we run ourselves on our own hosting, not by a third-party document service. We may update this list as our providers change, and will update this Policy when we do.

9. Overseas disclosure

As the table above shows, most of our infrastructure operates in the United States. This means Personal Information held in the platform may be disclosed to, stored in, or accessed from outside Australia.

Where we disclose Personal Information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles. Because these are internet services reachable from multiple locations, it is not always practicable to identify every country in which information may be held or accessed from. If you do not agree to your Personal Information being handled outside Australia, please do not submit it to us, and contact us using the details in section 18.

10. Direct marketing

We may use business contact details to tell you about our products, services and offers, by email or telephone, where you have consented or where it is within your reasonable expectation given your dealings with us. You can opt out at any time using the unsubscribe link in the message or by contacting us. We do not use sensitive information for direct marketing.

Service messages — approval requests, notifications, receipts and the like — are not marketing and are sent as part of running the platform.

11. Cookies and technical data

Our public website sets no cookies and runs no analytics or advertising scripts. The platform itself uses cookies that are necessary to keep you signed in securely; these are set by our authentication provider. If we ever introduce analytics, we will name the provider in section 8 and update this Policy.

We collect IP addresses and technical information such as browser and device details to operate, secure and troubleshoot the service. That information does not usually identify you on its own, but where we combine it with other Personal Information we hold, we treat it as Personal Information.

12. Sensitive information

Sensitive information is a subset of Personal Information — for example health, biometric, racial or ethnic information, or union membership. We do not seek to collect sensitive information, and the platform is not designed to hold it. Please do not upload documents containing it. If we do collect it, we will only do so with consent or where required or authorised by law.

Bank account details and Australian Business Numbers appearing on supplier invoices are not "sensitive information" as the Privacy Act defines it, but we treat them with the same care as the rest of the financial data in a workspace.

13. How we keep Personal Information secure

We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include encryption in transit and at rest, separation of each workspace's data with access checked on every request, role-based permissions and approval limits enforced on the server rather than only in the interface, multi-factor authentication, audit trails of significant actions, and monitoring for errors and unusual activity.

No method of transmission or storage is completely secure and we cannot guarantee absolute security, particularly where human error or malicious third-party activity is involved.

14. How long we keep Personal Information

We keep Personal Information for as long as it is needed to provide the service and for related purposes, and to meet our legal, accounting and record-keeping obligations. Because the platform holds financial records, customers commonly need their data retained for a number of years for tax and audit purposes, and we retain it for the life of the workspace on that basis.

When a workspace is closed we will, on request and for a reasonable period afterwards, make available a means for the customer to export their data. After that, we take reasonable steps to destroy or de-identify Personal Information that is no longer needed, except for copies held in routine backups or where the law requires us to retain it.

15. Access to, and correction of, your Personal Information

You may ask for access to, or correction of, the Personal Information we hold about you by contacting us using the details in section 18. We will respond within a reasonable time and may need to verify your identity first. In limited circumstances permitted by law we may decline a request, and if we do we will explain why.

If your request relates to information we hold on behalf of one of our customers — for example your details as they appear on an invoice inside their workspace — we will usually need to direct you to that business, because the records are theirs and they are responsible for them. We will help you identify who to contact where we reasonably can.

16. Data breaches

We maintain procedures to identify and respond to data breaches. If a breach involving Personal Information is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required. Where the information concerned is held on behalf of a customer, we will notify that customer promptly and work with them so they can meet their own obligations.

17. Anonymity and pseudonymity

Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym. It is usually not practicable in the platform itself: an approval trail is only meaningful if it records who actually approved something.

18. Complaints and how to contact us

If you have a question or a complaint about how we have handled your Personal Information, please contact our Privacy Officer:

BidLoop Pty Ltd (ACN 700 602 464)
Attention: Privacy Officer
Email: hello@bidloop.com.au
Postal address: Level 18, 360 Queen Street, Brisbane City QLD 4000

We will acknowledge your complaint, work with you to understand it, and aim to resolve it within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

19. Changes to this Privacy Policy

We may update this Policy from time to time to reflect changes in our practices or our legal obligations. We will publish the updated version here and change the "last updated" date above, and where a change is material we will take reasonable steps to notify you. By continuing to use the platform after an updated Policy takes effect, you acknowledge that Policy.