mySheet Account Deletion and Data Retention Policy
Effective date: 2 October 2026 Version: 1.1
1. Purpose
This policy explains how to delete a mySheet account, what deletion removes and keeps, what happens when an organisation cancels or a trial ends, and how long Logix 26 Pty Ltd trading as mySheet (ABN 71 649 099 730) keeps different kinds of information. It supports our obligation under APP 11.2 of the Privacy Act 1988 (Cth) to destroy or de-identify personal information we no longer need, and it should be read with our Privacy Policy.
Where this policy says something is done automatically, the service does it on a schedule. Where it describes a policy commitment, we apply it through our own processes and it is not yet fully automated. We say which is which.
2. Who controls the records
Businesses that use mySheet (our "customers") control the records they keep about their workers, such as timesheets, pay rates, leave and location records. We hold those records on the customer's behalf.
Employers in Australia must generally keep time and wage records for each employee for 7 years under the Fair Work Act 2009 (Cth) and the Fair Work Regulations 2009, and may have longer obligations under tax and superannuation law. Those obligations belong to the employer. mySheet is a timesheet and records service, not the employer's record-keeper of last resort. Each customer must export and keep its own copies of the records it is required to keep, particularly before its account is deleted.
Because the employer may be legally required to keep some records, deleting a worker's account does not remove every record about that worker. Section 5 explains what is kept.
3. The different kinds of deletion
- Stopping location collection. Turning off location access on your device stops new location records. It does not delete existing ones.
- Deleting your own account, or asking us to erase your personal data. This removes your personal details but keeps the employer's work records about you (section 5).
- An organisation cancelling its subscription. We aim to delete the organisation's data and files 60 days after cancellation (section 6). Automatic deletion is not yet operating, so information may remain beyond this target; we delete on request, by hand, within the times stated in this policy.
- A trial ending without a subscription. The same deletion is our aim 60 days after the trial started (section 7), on the same basis.
- Non-payment. An unpaid account is restricted, then cancelled, and then follows the cancellation timeline (section 8).
4. How to ask for deletion
- In the app. You can delete your own account, or make an erasure request for your personal data, from within the mySheet app.
- By email. Send your request to privacy@mysheet.au, addressed to Privacy Officer, Logix 26 Pty Ltd, from the email address linked to your account where possible.
We may need to verify your identity before acting on an emailed request. We will acknowledge it within 5 business days and complete it, or tell you why we cannot, within 30 days. Where the request concerns records your employer controls, we will tell your employer and work with it, because it may be required by law to keep some of them.
5. What deleting your account removes and keeps
Removed. When you delete your account or we act on your erasure request, we delete your own personal data held for your employer's payroll and staff records, including:
- your TFN, bank BSB, bank account number, bank account name and superannuation details;
- your address and its map coordinates;
- your pay rates, wages and wage history;
- your leave and availability records; and
- the consents you gave in the app.
Kept as the employer's records. We keep the following because they are your employer's work records, which it may be legally required to keep:
- your timesheets and the jobs you worked;
- location records and geofence events captured during your shifts;
- clock-in selfies; and
- attachments.
These are kept for the periods in section 10, or until the employer's organisation is deleted, whichever is earlier.
Owner and employee requests. If the organisation owner requests erasure, we delete the whole organisation by hand, acknowledging the request within 5 business days and completing it within 30 days, and this cannot be undone. An individual employee's erasure request is actioned straight away for that person's own data.
Other records. Sign-in, terms acceptance, consent, session, audit, notification, email and connected-service log records are handled under the retention schedule in section 10. You can ask us to delete your sign-in record with our identity and sign-in provider by emailing us.
6. When an organisation cancels
An organisation can cancel its subscription at any time from within the app. Cancellation takes effect at the end of the current billing period, and then:
| Day | What happens |
|---|---|
| Day 0 | The subscription ends and the account enters a 30-day grace period. The organisation can reactivate. |
| Day 30 | The account becomes view-only. Records can still be viewed and exported, and the organisation can reactivate. |
| About day 53 | We aim to email the organisation a warning that its data will be permanently deleted. This is not guaranteed while automatic processing is not operating. |
| Day 60 | Our target is to permanently delete the organisation's data and stored files. While automatic deletion is not operating, this is done by hand on request and is not guaranteed to happen on day 60. It includes timesheets, rosters, leave, pay records, TFNs and bank details, location records, geofence events, selfies and attachments. |
Because automatic deletion is not yet operating, this deletion is done by hand on request, within the response times in section 4. Audit logs for the organisation are deleted when its data is deleted. The organisation and user records, such as name, date of birth and email, persist unless the user is erased. User sign-in records are kept after this deletion, because a person may belong to more than one organisation, unless the user asks us to erase them separately.
Export before day 60. Once the day 60 deletion has run, the organisation's data cannot be recovered. The customer must export everything it needs, and keep it for as long as the law requires, before then.
7. When a trial ends
A new organisation receives a 30-day trial, and no card is needed. If the trial ends without a paid subscription:
- the account becomes view-only at the end of the trial (day 30 after sign-up), and the organisation can still export its records or subscribe; and
- we aim to permanently delete the organisation's data and stored files 30 days later (day 60 after sign-up), by hand on request, because automatic deletion is not yet operating.
Anyone who enters real worker, timesheet or pay records during a trial must export them before day 60 if they do not subscribe.
8. Non-payment
If a subscription payment fails, a notice is shown in the app asking for payment details to be updated. If payment is still outstanding, we may restrict, suspend or cancel an account for non-payment after reasonable notice. If the subscription is cancelled, the cancellation timeline in section 6 then applies, ending with deletion at our 60-day target.
Export and account deletion remain available throughout this period.
9. Exporting data
- Organisation export. An organisation's administrators can download its records as a ZIP file from within the app.
- Reports. Timesheet and other reports can be downloaded as CSV files.
- Personal export. Each user can download their own personal data. The TFN is masked so that only the last 3 digits are shown.
Export is available while the account is active, view-only or restricted for non-payment, up until deletion. If you cannot use the export tools, email hello@mysheet.au.
10. Retention schedule
| Information | How long we keep it | How this is applied |
|---|---|---|
| All organisation data and stored files after cancellation or trial expiry | Our aim is deletion 60 days after cancellation, or 60 days after sign-up for a trial that does not convert | Target; automatic purging is not yet operating, so done by hand on request |
| Timesheets, rosters, leave, pay rates and wage history while the subscription is active | Kept while the subscription is active, so the customer can meet its 7-year record-keeping obligations. Our policy is to delete or de-identify these records 7 years after they were created. | Policy commitment; not yet automated |
| Location records and geofence events | Kept as part of the timesheet records they belong to, for the same period as those records | Policy commitment; not yet automated |
| Clock-in selfies | A per-organisation setting, with a default of 90 days. We aim to delete them at the end of that period. | Target; automatic purging is not yet operating |
| Attachments | Kept with the records they are attached to, for the same period as those records | Policy commitment; not yet automated |
| TFNs, bank BSBs and account numbers | Until the worker's personal data is erased, the employer tells us they are no longer needed, or the organisation is deleted, whichever is earliest | Deleted on request or with the organisation |
| Audit logs (most types) | We aim to delete them after 7 years. Audit logs for an organisation are also deleted when the organisation is deleted. | Target; automatic purging is not yet operating |
| Notifications and email send logs | We aim to delete them after 90 days | Target; automatic purging is not yet operating |
| External API logs (for example Xero calls) | We aim to delete them after 30 days | Target; automatic purging is not yet operating |
| Payment processor event records | We aim to delete them after 90 days | Target; automatic purging is not yet operating |
| Import CSV files | We aim to delete them after 30 days | Target; automatic purging is not yet operating |
| Session records | We aim to delete session records when the session expires | Target; automatic purging is not yet operating |
| Login and IP address records | Held in audit logs (most types, we aim to delete after 7 years, and organisation subscription events after about 2 years) and in external API logs (we aim to delete after 30 days). These follow the audit log and external API log rows above, not the session row. | Target; automatic purging is not yet operating |
| Terms acceptance and consent records | For as long as the account exists and up to 7 years afterwards, as evidence of what was agreed, then deleted or de-identified | Policy commitment; not yet automated |
| User sign-in records | Until the user deletes their account or asks us to erase them | On request |
| Temporary cache of notification images, including selfies | Up to 24 hours | Automatic expiry |
| Error reports held by our error monitoring provider | For the retention period set in our error monitoring account, which we aim to keep to 90 days or less | Provider setting |
| Contact form enquiries in our mailbox | Up to 2 years after our last contact, unless the enquiry becomes part of a customer relationship | Policy commitment; not yet automated |
| Billing records | As long as needed for tax and accounting law, generally 5 years after the transaction | Policy commitment; payment records are also held by our payment processor under its own obligations |
Our policy is to delete the information or de-identify it so that it no longer identifies anyone when a period ends. The target periods above do not currently trigger deletion or de-identification automatically: automatic purging is not operating, and we currently delete information manually on request within the response times in section 4, so information may remain beyond those targets. If we are required by law, or reasonably need, to keep information for longer, for example because of a legal claim or a regulator's request, we will keep it only for as long as that requirement lasts.
11. Backups
Our database provider keeps backups so that the service can be restored after a disaster. Deleted information may remain in those backups for a short period after deletion, until the backups are overwritten in line with our provider's backup schedule. We do not restore deleted information from backups except to recover the service after a disaster. If a restore ever brings back information that had been deleted, we will delete it again.
12. Information on your device or browser
The mySheet application keeps some information in your browser or on your device so that it works, including your sign-in session and a queue of clock events recorded while you were offline. This information is removed when you sign out or clear the app's storage, or, for queued clock events, once they have been sent to mySheet. Uninstalling the mobile app generally removes the information it stores on the device, although your device's own backup settings may affect this. Details are in our Cookie and Browser Storage Policy.
13. Tax file numbers
We hold TFNs only on behalf of employers, under the Privacy (Tax File Number) Rule 2015. TFNs are encrypted at field level, are never sent to Xero or any other connected service, and are deleted as set out in section 10. If an employer no longer needs a worker's TFN for a purpose the law permits, it should remove it or ask us to delete it, and we will do so within 30 days.
14. Access, correction and complaints
You can ask for access to, or correction of, the personal information we hold about you by emailing privacy@mysheet.au. We will acknowledge your request within 5 business days and respond within 30 days.
If you have a complaint about how we have handled your personal information, email Privacy Officer, Logix 26 Pty Ltd at privacy@mysheet.au or write to PO Box 502, Caloundra QLD 4551. We will acknowledge it within 5 business days and give you a written response within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
15. Document details
- Effective date: 2 October 2026
- Version: 1.1
- Previous version: 1.0, effective 30 September 2026

