Legal

Privacy Policy

How Tockly collects, uses, stores and protects personal information.

Last updated 13 September 2026

1. Who we are

Tockly is operated by Tockly Limited, a New Zealand limited company (company number 9459698; NZBN 9429053967008). Tockly Limited is the agency responsible for personal information handled through Tockly. We provide invoice-management and payment-reminder software.

Privacy Officer: contact@tockly.ai
Registered office: Level 6, 135 Broadway, Newmarket, Auckland 1023, New Zealand.

2. Our role

For account, subscription, security, support and service-operation information, Tockly generally determines why and how information is handled. For invoice, customer, debtor and reminder-recipient information supplied or imported by a business using Tockly (Customer Data), that business generally decides whom to contact, why and when. Tockly processes Customer Data on that business’s instructions, except where law requires otherwise.

3. Information we handle

  • Account and business details, including names, email addresses, roles, workspace settings and authentication records.
  • Subscription status, transaction identifiers and limited billing metadata.
  • Customer and invoice information, including contact details, invoice numbers, amounts, dates, currency, status, notes and attachments.
  • Information received through authorised integrations such as Xero and MYOB, or QuickBooks through Intuit, including organisation identifiers, contacts, approved unpaid sales invoices, status information and connection credentials.
  • Reminder activity, including recipients, delivery events, email opens, link use, promises to pay, disputes and reported payment dates.
  • Technical and security information, including IP address, browser, device, timestamps, session records, errors and diagnostic logs.
  • First-party website analytics across Tockly’s public websites, including Tockly Equine, such as the public page visited, approximate country, region and city, referring website, timestamp, anonymous browser and session identifiers, and an automated-traffic indicator. These identifiers are used to distinguish visitors, sessions and page loads. Tockly does not store IP addresses in its page-view analytics records.

4. Where information comes from

Information may come directly from an account holder or reminder recipient; from the business using Tockly; from an authorised connected service such as Xero, MYOB or QuickBooks; automatically through use of Tockly, its emails and security systems; or from service providers needed to operate and secure Tockly.

5. How we use information

We use information to create and administer accounts; import, organise and store invoices and contacts; schedule and send reminders; record delivery and responses; update records after payment; provide support; operate subscriptions; secure the service; prevent misuse; meet legal obligations; and establish or defend legal rights.

6. Reminder recipients and indirect collection

Tockly often receives recipient information from the business using Tockly or through Xero, MYOB or QuickBooks rather than directly from the recipient. The subscribing business must have authority to supply that information and instruct the communication. Reminders identify the business responsible for the invoice and that Tockly sends the message on its behalf. A recipient can contact that business or Tockly about a wrong recipient, privacy concern or disputed invoice.

7. Email tracking

Reminder emails may contain a small tracking image or uniquely coded links. These may indicate that an email was opened, a link was used or a response was submitted. Tracking can be affected by email-client privacy settings and is not always accurate. We use it to show follow-up activity, support reminder workflows and protect link security.

8. When information is disclosed

We disclose information only as reasonably necessary to authorised workspace users, selected reminder recipients, connected services, service providers, professional advisers, regulators or other parties required by law. Additional reminder recipients are delivered messages separately or by blind copy so their addresses are not disclosed to one another.

9. Service providers and overseas processing

Tockly currently relies on OpenAI for the Sites platform; Cloudflare for application computing, database, file storage and approximate country detection; Resend for reminder email; Microsoft and Google when a customer chooses to connect its own business mailbox; Microsoft for a fallback delivery route; GoDaddy for domain, DNS and Microsoft 365 administration; ExchangeRate-API for indicative currency conversion rates; and Xero, MYOB and Intuit for customer-authorised accounting integrations. Exchange-rate requests do not include customer or account information. These providers may process information outside New Zealand through their global infrastructure. Their own terms and privacy safeguards also apply.

Stripe may be used when paid checkout is enabled. Tockly uses its own first-party page-view analytics and does not currently use a third-party advertising or analytics provider or a third-party SMS or telephony provider. OpenAI processes questions submitted to Tockly Help to generate product-support answers.

10. AI and automated tools

Tockly Help uses a generative AI service supplied by OpenAI to answer product-support questions. Tockly sends the text a signed-in user types into the help conversation and a short portion of that conversation; it does not automatically send contacts, invoices, amounts or data from connected accounting services. Users should not enter personal, financial or confidential information into Tockly Help. Responses may be inaccurate and should be checked before relying on them. Tockly does not use Help conversations to make solely automated decisions that produce legal or similarly significant effects, and requests are made with provider-side response storage disabled.

11. Security

Passwords are uniquely salted and hashed using PBKDF2 with SHA-256 and are not stored in readable form. Tockly uses encrypted connections, access controls, credential protection and restricted administrative access. Users are automatically signed out after 15 minutes of inactivity. No online system can be guaranteed completely secure.

12. Retention and deletion

  • Open invoice records remain available until deleted by the user or the account is closed. Paid invoices, their attachments and their invoice-specific activity history are automatically deleted from active storage 30 days after payment is recorded.
  • Deleted items are removed from active application storage, subject to reasonable processing time and provider recovery systems.
  • Deleted database information may remain in Cloudflare D1 recovery history for up to 30 days.
  • After verified account closure, reminders stop and the workspace may remain recoverable for up to 30 days before active Customer Data is deleted. Residual provider recovery copies may take up to a further 30 days to expire.
  • Security, delivery, suppression and anti-abuse records may be kept for up to 12 months, or longer where needed for an investigation or legal obligation.
  • Tockly’s own billing, tax and legally required business records may be kept for at least seven tax years.

Disconnecting Xero, MYOB or QuickBooks stops future access through that connection. Imported open invoices remain until deleted or paid; paid invoices follow the automatic 30-day deletion rule above.

13. Your choices and rights

You may ask for access to or correction of personal information Tockly holds about you. Depending on applicable law, you may also have rights to deletion, portability, restriction, objection or complaint. Some requests about Customer Data must be handled first by the business that supplied it. Email contact@tockly.ai with enough information for us to identify the relevant account, invoice or communication.

14. Children

Tockly is a business service and is not directed to children under 18. Contact us if you believe a child’s information has been supplied without proper authority.

15. Breaches and complaints

We investigate suspected privacy and security incidents and make notifications required by applicable law. You may complain to our Privacy Officer or to the privacy regulator in your country, including the New Zealand Office of the Privacy Commissioner.

16. Changes

We may update this policy as Tockly’s features, providers or legal obligations change. We will publish the current version and provide additional notice where a change materially affects how information is used or disclosed.