mySheet Privacy Policy
Effective date: 2 October 2026 Version: 1.1
1. Who we are
mySheet is a timesheet, rostering and workforce records service supplied by Logix 26 Pty Ltd trading as mySheet ("mySheet", "we", "us" or "our").
- ABN: 71 649 099 730
- Postal address: PO Box 502, Caloundra QLD 4551
- Website: https://mysheet.au (marketing website) and https://app.mysheet.au (the mySheet application)
- Privacy contact: Privacy Officer, Logix 26 Pty Ltd, privacy@mysheet.au
This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We have written it on the basis that we are bound by the APPs, and we do not rely on the small business exemption. Because we hold tax file number (TFN) information, we are also bound by the Privacy (Tax File Number) Rule 2015 (TFN Rule) and by the Notifiable Data Breaches scheme for that information in any event.
This policy covers the mySheet web application, the mySheet mobile app, and our marketing website at mysheet.au.
2. Google user data
If you choose to sign in to mySheet with Google, this section explains exactly what we receive from Google, why, where it goes and how you can remove it. It is a summary of the rest of this policy, which also applies.
What we receive. When you sign in with Google, Google tells our sign-in service your name, your email address, the web address of your Google profile picture (if you have one) and your Google account identifier. We ask Google only for basic email and profile information, using the standard sign-in permissions (email and profile, with openid). We do not ask for, and do not receive, your Gmail, contacts, calendar, Drive files or any other Google data, and we do not access any Google service after you sign in.
Why we use it. We use it only to create and secure your mySheet account, to sign you in, to show your name and email address to you and to the other authorised users in your organisation, to send you service emails about your account, and to keep security and audit records. We do not use it for any other purpose.
Where it is stored. It is stored by our sign-in provider, using a tenant configured for Australia, and in our database in Sydney, Australia. See sections 9 and 10 for the categories of providers involved and where they operate.
Who it is shared with. Your name and email address are visible to your employer's authorised administrators and managers in mySheet. We share it with service providers only to the extent needed to run mySheet (for example cloud hosting, the database, sign-in and email delivery), as described in section 9. We do not share it with anyone else, except where the law requires.
What we do not do. We do not sell Google user data. We do not use it for advertising, including personalised or retargeted advertising. We do not use it to build or train artificial intelligence or machine learning models. We do not allow people to read it, other than where needed for security, to provide support you have asked for, to comply with law, or where the data has been aggregated and anonymised.
How long we keep it. We keep it while your account is active. If you delete your account, or ask us to erase it, we remove it as described in section 13 and in our Account Deletion and Data Retention Policy. If your employer's organisation is deleted but you have not deleted your account, your sign-in record is kept until you ask us to erase it.
How to delete it. You can delete your account in the app, or ask us to delete it by emailing privacy@mysheet.au (see our account deletion page). You can also remove mySheet's access from your Google Account settings at any time, which stops further sign-ins with Google; it does not by itself delete your mySheet account.
Google API Services User Data Policy. mySheet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you sign in with Apple, we receive the name and email address (or Apple's private relay address) that you choose to share, and we use it in the same way. You can stop using Sign in with Apple for mySheet in your Apple Account settings; this does not by itself delete your mySheet account.
3. Our two roles: employer records and our own records
mySheet is used by businesses (our "customers") to record their workers' time, rosters, leave, jobs and related details.
Records your employer controls. When a business uses mySheet, it decides which workers, customers and jobs to record, what information to enter, which features to switch on (for example location recording or clock-in selfies) and what the records are used for. The business controls those records. We hold and process them on the business's behalf so that we can provide the service to it. If you are a worker, your employer is responsible for telling you how it handles your information at work, and each employer that uses mySheet must give its workers its own workplace privacy notice. Questions about why your employer collects something, or requests to change what your employer records, are usually best directed to your employer first. We will help both you and your employer respond.
Some private sector employers are exempt from the Privacy Act for their employee records. That exemption belongs to the employer only. It does not apply to mySheet, and we handle all personal information in mySheet in line with this policy.
Records we control. We also handle some personal information for our own purposes, such as account sign-in, subscriptions and billing, security, support, evidence of terms acceptance, service emails and enquiries sent to us through our website.
Children. mySheet is a workplace tool for businesses and is not directed at children. A business may record workers who are under 18, for example young employees or apprentices. The business decides what is recorded about them and is responsible for telling them, and their parent or guardian where that is needed. If you think information about a child has been recorded without proper authority, email privacy@mysheet.au and we will look into it.
4. Personal information we collect and hold
What we hold depends on which features a customer uses and what its administrators and workers enter.
Summary of what we collect
| Category | Examples | Why we collect it | Kept for |
|---|---|---|---|
| Account and sign-in | Name, email address, date of birth, sign-in and two-factor details, Google sign-in profile (name, email, profile picture address, account identifier) or Apple sign-in (name where supplied, email or relay address) | To create and secure your account and let you sign in | While your account is active; see section 12 |
| Records entered on behalf of an employer | Timesheets, rosters, leave, jobs, pay rates, TFN and bank details where the employer records them | So the employer can run its own workforce records; we hold them on its behalf | While the employer's subscription is active, then as in section 12 |
| Device and usage | IP address, browser and device details, session and audit logs, error reports, aggregate website page views and interactions | To run, secure and improve the service and website | As in section 12; website analytics are aggregate and cookieless |
| Location (only if the employer switches it on) | Location while on shift, job site arrival and departure | To record where time was worked, as the employer requires | With the timesheet record |
| Clock-in selfies (only if the employer switches them on) | A photo taken at clock-on, with its location | As an attendance record for the employer | Per-organisation setting, default 90 days (target; see section 12) |
| Billing | Organisation and billing contact details, plan status (card details go to our payment processor) | To take payment and calculate tax | As needed for tax and accounting law |
| Enquiries | Name, email, business type, message | To reply to you | Up to 2 years after last contact |
The detail follows.
Account and sign-in details
- Name, preferred name, email address and date of birth of each user.
- Two-factor authentication secrets and recovery codes, where a user turns on two-factor sign-in.
- Sign-in details handled by our identity and sign-in provider, including email address, password credentials and basic profile details (name, email address and picture) if you sign in with Google or Apple.
- Records of when you accepted our terms and gave any consent within the app, including the IP address and browser or device details (user agent) at that time.
- Session records, including IP address and user agent.
Worker details entered by or for an employer
- Phone number, residential address (and the map coordinates of that address) and next-of-kin name and phone number.
- Employment details, pay rates, wages and wage history.
- Tax file number, bank BSB, bank account number, bank account name, superannuation fund and member number.
- Payroll settings, including the tax scale and the student and training support loans (STSL) flag.
- Leave requests, availability and roster details.
Timesheets, jobs and location
- Clock-on and clock-off times, timesheet hours, approvals and the jobs worked.
- Location recorded while you are on shift, and geofence events (records that a device entered or left a job site area set by the employer). See section 7.
- Clock-in selfies, where the employer's plan includes that feature and the employer has switched it on. Each selfie is stored with the location at which it was taken. See section 7.
- Files attached to records (attachments).
- Customer signatures captured on jobs.
Customers and jobs of the business
- Names, addresses, map coordinates and contact details of the business's own customers and job sites, as entered by the business.
Billing details
- Organisation name, the organisation's billing email address and the email addresses of users involved in billing, plan and subscription status, and any referral code used.
- Card and payment details are entered directly into our payment processor. We do not store full card numbers.
Communications and technical records
- Notifications sent within mySheet and by push notification, including their content and delivery details.
- Records of emails we send, including the recipient, the kind of email and its content.
- Records of calls between mySheet and the accounting software a customer connects (such as Xero), which can include the information exchanged.
- Audit logs recording actions taken in an organisation's account, including the user, the time, the IP address and user agent.
- Push notification device tokens.
- Error reports sent to our error monitoring provider (see section 9).
Enquiries through our website
- If you use the contact form at mysheet.au, your name, email address, optional business type and message. See section 17.
Free-text fields, notes and attachments can contain whatever a user chooses to type or upload. We ask users not to add sensitive information that the business does not need.
We do not intentionally collect health information, biometric templates or other sensitive information. Clock-in selfies are photographs used as a record of attendance. mySheet does not perform face recognition or face matching on them.
5. How we collect personal information
We collect personal information:
- directly from you, when you create an account, fill in your profile, clock on or off, request leave or contact us;
- from your employer's administrators and managers, who may enter or import details about you;
- from your device, when you use the app and allow access to location, camera or notifications;
- from Xero, if your employer connects its Xero account (see section 9);
- from our payment processor, in connection with subscriptions and payments;
- from Google or Apple, if you choose to sign in with them (see section 2); and
- from our service providers, for example sign-in details from our identity provider and error details from our monitoring service.
Where a customer gives us information about another person, the customer must be authorised to do so and must give that person any notice required by law.
6. Why we collect, use and disclose personal information
We collect, use and disclose personal information to:
- create and secure accounts and let people sign in;
- provide the timesheet, rostering, leave, job, location, selfie, reporting and export functions the customer has chosen;
- let each customer manage its workers and review and approve their time;
- process subscriptions and payments and calculate tax;
- send service emails and notifications, such as invitations, approvals, billing notices and deletion warnings;
- connect to Xero where the customer has asked us to;
- operate, maintain, troubleshoot and support the service;
- detect, prevent and investigate security incidents and misuse;
- keep evidence of terms acceptance, consents and actions taken in accounts;
- respond to enquiries, and to access, correction, deletion and complaint requests; and
- comply with our legal obligations.
We do not sell personal information. We do not use personal information for advertising, and the mySheet app and web application contain no advertising or analytics trackers.
We will only use or disclose personal information for a secondary purpose where the APPs permit it, for example where you would reasonably expect it and it is related to the purpose of collection, where you consent, or where it is required or authorised by law.
7. Location and clock-in selfies
These features are controlled by your employer. Your employer must tell you about them in its own workplace privacy and monitoring notice, and must comply with any workplace surveillance or tracking device laws that apply where you work.
Location while on shift. When you clock on or off, the app can record your location at that time if you have allowed location access. While you are clocked on, the mySheet mobile app can record your location at intervals, and it asks for permission to access your location in the background so that this can continue when the app is not open. Your employer can also set job site areas (geofences), and the app records when your device enters or leaves those areas during your shift. These location records are stored with your timesheet records.
Not while you are off shift. mySheet is designed to keep location only while you are on shift. If your device sends a location while you are not clocked on, our server discards it and does not store it.
Your choices. You can switch off location access, including background location, in your device settings at any time. Doing so stops further location collection, but it does not delete location records already stored. If your employer requires location for clocking on, switching it off may affect how you record your time, so please speak with your employer.
Clock-in selfies. On plans that include this feature, an employer can require a photo when a worker clocks on. The photo is stored in our database together with the location where it was taken and forms part of the timesheet record. To show a selfie to a manager in a notification, the image may also be held temporarily in a short-lived cache for up to 24 hours.
Attachments. Photos and other files attached to records are stored privately. We remove embedded location and camera information (EXIF and GPS data) from attached images when they are stored.
Who can see this information. Location records, geofence events and selfies are available to the administrators and managers your employer authorises in mySheet. They are not shared with other businesses.
8. Tax file numbers, bank details and pay information
Employers may record a worker's TFN, bank BSB and account number in mySheet so that the employer has them available for its own payroll and superannuation purposes. mySheet is not a payroll system and does not lodge anything with the Australian Taxation Office.
We handle TFN information in line with the TFN Rule:
- we collect, hold and use TFNs only on behalf of the employer, and only so the employer can use them for the tax and superannuation purposes the law permits;
- we do not use a TFN to identify you, to match records or for any other purpose;
- we do not send TFNs to Xero or to any other connected service, and we do not disclose them to anyone other than the employer's authorised users, except where the law requires;
- TFNs, bank BSBs and bank account numbers are protected with field-level AES-256-GCM encryption in our database, in addition to the security measures in section 11;
- when you download your own personal data, your TFN is masked so that only the last 3 digits are shown; and
- TFNs are deleted when a worker's personal data is erased, when the employer's organisation is deleted, or when the employer instructs us that the TFN is no longer needed.
You do not have to give your TFN, and it is not an offence to decline. If you do not give it to your employer, tax may be withheld from your pay at the highest rate. Your employer should explain this in its TFN declaration process.
Bank account names, superannuation fund names and member numbers, pay rates and wage history are protected by the security measures in section 11 but do not have the additional field-level encryption.
9. Who we disclose personal information to
We disclose or make personal information available to:
- the customer organisation and the users it authorises in mySheet;
- the service providers listed below, who help us run mySheet and who may only use the information to provide their services to us;
- Xero, when a customer connects its Xero account;
- our professional advisers, insurers and, if our business is sold or restructured, a buyer that agrees to handle personal information in line with this policy (for information received from Google, only with your prior consent); and
- government authorities, courts or others where we are required or authorised by law.
Who we share it with, by category
We do not name our individual back-end suppliers in this policy. We use the following kinds of provider, each of which may only use the information to provide its services to us:
| Category of recipient | What they do for us | Personal information involved | Where they are likely to be located |
|---|---|---|---|
| Cloud hosting provider | Runs the mySheet application servers and serves the web application | All information handled by the service | Servers in Sydney, Australia; the service that delivers the web application files may use infrastructure outside Australia |
| Database provider | Hosts the mySheet database | All stored service information, including selfies | Sydney, Australia |
| Identity and sign-in provider | Handles sign-in, including optional Google and Apple sign-in | Email address, password credentials, profile details, sign-in records | Configured with an Australian tenant; the provider may access or process information outside Australia to provide and support the service |
| Google and Apple, if you choose to sign in with them | Identity providers | Your sign-in with that provider and basic profile details | Outside Australia, including the United States |
| File storage provider | Stores attachments in private storage | Attached files, with image location data removed | May be outside Australia |
| Temporary data store provider | Holds short-lived data used to run the service, such as notification images for up to 24 hours | Temporary copies of notification content, which can include a selfie | May be outside Australia |
| Payment processor | Subscription payments and automatic tax calculation | Organisation name and ID, billing and user email addresses, referral code, card and payment details you give the processor | United States and other countries |
| Email delivery providers | Send service emails and deliver contact form enquiries to us | Recipient email address and the content of the email; for the contact form, your name, email address, optional business type and message | United States |
| Error monitoring provider | Monitors server errors so we can fix them | Error details and technical context, after filters intended to remove TFNs, BSBs, location, tokens and email addresses (which may not remove every occurrence) | United States |
| Push notification and mapping providers | Deliver push notifications to devices; display maps and look up addresses | Device token, notification title, text and link; addresses and map coordinates | Global infrastructure, which may include locations outside Australia |
| Website analytics providers | Count visits and interactions on our marketing website, without cookies and without personal profiles | Page address, referring page, browser, operating system, screen size, time zone, device type and the actions taken (for example which demo was opened), plus your IP address, which the provider receives in order to deliver the request and may use to estimate an approximate location. No names, email addresses, form content or typed text | United States and other countries |
| Website delivery provider | Delivers and protects our marketing website, runs the contact form function and counts page views in aggregate | IP address, browser signals, request details and contact form content | Global network, which may include locations outside Australia |
| Bot-check provider | Checks that a password sign-in is made by a person, where enabled | IP address and browser signals | Global network, which may include locations outside Australia |
| Email content providers | Supply a font and an image shown in our emails | Your IP address and device details when you open an email | Global infrastructure, which may include locations outside Australia |
| Accounting software you choose to connect (for example Xero) | Optional integration, only when the customer connects its own account | See below | The provider's infrastructure, which may be outside Australia |
Xero. Xero is available on plans that include it, only when the customer connects its own Xero account. The connection brings employees, pay rates and payroll calendars from Xero into mySheet. The information exchanged through the connection can include employee identity and contact details and pay details. TFNs are never sent to Xero. Once information reaches Xero, Xero handles it under its own terms with the customer.
We do not sell personal information. We do not use advertising trackers or cross-site tracking technologies in mySheet or on our website. On our marketing website we use cookieless analytics, described in section 17.
A list of our service providers and where they are located is available on request from our Privacy Officer at privacy@mysheet.au.
We will update this policy before we start using a new category of service provider that receives personal information.
10. Overseas disclosure
Our application servers run in Sydney, Australia, and our database is hosted in Sydney, Australia. However, not all personal information stays in Australia, and we do not say it does. Our identity and sign-in provider uses an Australian tenant but may access information from outside Australia. Our file storage, temporary data store, email delivery, payment, error monitoring, push notification, mapping, website analytics and website delivery providers, and the accounting software a customer chooses to connect, may store or process information outside Australia. Countries in which recipients are likely to be located include the United States and other countries in which those providers or their infrastructure operate. Copies in provider backups may also be held outside the location of the primary system for a limited period.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs, including by using providers whose contract terms deal with the security and confidentiality of the information. We remain accountable for how those providers handle it in accordance with the Privacy Act.
11. How we protect personal information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. Our measures include:
- encryption of information in transit between your device and our service;
- field-level AES-256-GCM encryption of TFNs, bank BSBs and bank account numbers;
- sign-in through our identity provider, and access controls that limit each user to their own organisation and to the functions their role allows;
- private file storage, with location data removed from attached images;
- filters intended to remove TFNs, BSBs, location, tokens and email addresses from error reports before they are sent to our monitoring service (the filters may not remove every occurrence); and
- limiting access by our own personnel to what is needed to run and support the service.
No system is completely secure. We do not claim any security certification. You can help by keeping your sign-in details private and telling us promptly at hello@mysheet.au if you suspect unauthorised access.
12. How long we keep personal information
Our retention policy is to delete or de-identify personal information when it is no longer needed for the purposes in this policy and retention is not legally required. Automatic deletion and purging are not yet operating; deletion currently occurs manually on request, so information may remain beyond our retention targets. The main points are:
- while a customer's subscription is active, its records remain available to it;
- employers must generally keep time and wage records for 7 years under the Fair Work Act 2009 (Cth) and the Fair Work Regulations. Those obligations belong to the employer, which must export and keep its own copies;
- after a customer cancels, or a trial ends without a subscription, we aim to delete the customer's organisation data and stored files 60 days after cancellation takes effect (or 60 days after sign-up for a trial that does not convert). Automatic deletion is not yet operating, so information may remain beyond these targets; we delete on request, by hand, within the times stated in this policy, as described in our Account Deletion and Data Retention Policy;
- we aim to delete most audit log types after 7 years, notifications and email logs after 90 days, external API logs after 30 days, payment processor event records after 90 days and import CSV files after 30 days. We aim to delete clock-in selfies at the end of a per-organisation setting, with a default of 90 days. Automatic purging of these is not yet operating. Audit logs for an organisation are also deleted when the organisation's data is deleted; the organisation and user records, such as name, date of birth and email, persist unless the user is erased;
- deleted information may remain in our providers' backups for a limited period, as explained in the Account Deletion and Data Retention Policy; and
- contact form enquiries are kept for up to 2 years after our last contact with you, unless the enquiry becomes part of a customer relationship.
13. Access, correction and deletion
You can ask for access to the personal information we hold about you, ask us to correct it, or ask us to delete it.
- In the app. You can view and update much of your profile in the app, download a copy of your own data (your TFN is shown masked), and delete your account.
- By email. Send your request to privacy@mysheet.au, addressed to Privacy Officer, Logix 26 Pty Ltd.
We may need to verify your identity before acting on a request. There is no charge to make a request. We will acknowledge your request within 5 business days and respond within 30 days.
Where the information forms part of records your employer controls, we will usually work with your employer to respond, because your employer may have a legal obligation to keep some records, such as timesheets. If we refuse a request, in whole or in part, we will tell you why in writing (unless it would be unreasonable to do so) and how you can complain. If we do not correct information, you can ask us to attach a statement that you believe it is inaccurate.
What account deletion removes and keeps is set out in our Account Deletion and Data Retention Policy.
14. Complaints
If you have a concern about how we have handled your personal information, please contact Privacy Officer, Logix 26 Pty Ltd at privacy@mysheet.au or write to us at PO Box 502, Caloundra QLD 4551. We will acknowledge your complaint within 5 business days, look into it and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
15. Data breaches
We assess suspected eligible data breaches promptly, taking all reasonable steps to complete the assessment within 30 days, and notify eligible breaches as soon as practicable.
If we become aware of a data breach involving personal information we hold, we will act promptly to contain it and assess it. Where a breach is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where the breach involves records a customer controls, we will also notify that customer without undue delay so that it can meet its own obligations.
16. Emails and direct marketing
We send service emails that you need in order to use mySheet, such as invitations, approval notices, billing notices and deletion warnings. These are not marketing messages.
We do not currently send marketing emails. If we do in future, we will only send them with your consent in line with the Spam Act 2003 (Cth) and APP 7. Each marketing message will identify us and include a simple way to unsubscribe, and we will act on an unsubscribe request within 5 business days.
17. Our marketing website and contact form
Our marketing website at mysheet.au is delivered through a content delivery and security network, which receives your IP address and request details in order to deliver the site. We do not set cookies on it. If you choose light or dark mode, your choice is saved in your browser's local storage.
Website analytics. We use cookieless analytics to count visits and see which parts of the site are used (for example which demo was opened, which plan toggle was used, or that the contact form was sent). Our analytics use no cookies and no browser storage, create no personal profiles, make no session or screen recordings, and never capture what you type, including in the contact form. Each event includes the page, the referring page (without query strings), your browser, operating system, screen size, time zone and device type, and for a few actions a short label such as the demo name or plan. The contact form event carries only the industry you chose. Identifiers last only for the current page visit. Our analytics provider receives your IP address in order to deliver the request and may use it to estimate an approximate location. Our own analytics are switched off if your browser sends Do Not Track, or for the rest of that page visit if you add ?no-track to the address. Our website delivery provider also counts page views with its own cookieless measurement, which records the page, referrer, browser type and page-load timings and receives your IP address; Do Not Track and ?no-track do not switch that off. Our analytics providers are in the United States and other countries (see section 10).
If you use our contact form, we collect your name, email address, optional business type and message. The form is processed by a serverless function and delivered to our mailbox by our email delivery provider, with your email address set as the reply address. We use your IP address only briefly, in memory, to limit the number of messages that can be sent; it is not stored, logged or included in the email. The function does not log your name, email address or message. We use your enquiry only to reply to you. We do not add you to a mailing list.
More detail about browser storage is in our Cookie and Browser Storage Policy.
18. Changes to this policy
We may update this policy when our service, providers or legal obligations change. We will publish the updated policy on our website with a new effective date and version. If a change materially affects how we handle personal information already collected, we will also tell customers by email or in the app before the change takes effect.
19. Contact us
- Privacy Officer, Logix 26 Pty Ltd
- Logix 26 Pty Ltd trading as mySheet, ABN 71 649 099 730
- PO Box 502, Caloundra QLD 4551
- Email: privacy@mysheet.au
20. Document details
- Effective date: 2 October 2026
- Version: 1.1
- Previous version: 1.0, effective 30 September 2026

