Your data, handled plainly.
Last updated: September 2026
Who we are
SMSF Core Australia Pty Ltd (ACN 697 503 352) provides an online record-keeping and compliance tool for self-managed superannuation fund trustees. We are based in Sydney, Australia. Contact us about privacy at hello@smsfcore.com.
This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
SMSF Core is an information and calculation tool. It is not a licensed financial service and does not provide financial product advice. How we handle your data does not change that.
What we collect
We collect only what the service needs to run:
- Account information: your email address, used for sign-in.
- Fund data you provide: the fund details you enter and the transaction, parcel and dividend data you upload or enter, including statements you forward to your fund's statement forwarding address. Forwarded statements are processed to pre-fill records for your review.
- Billing information: handled by Stripe. We never see or store your full card details.
- Usage information: cookie-free, aggregate analytics via Plausible, plus short-lived server logs (for example, IP addresses for rate limiting and security).
How we use it
We use your information to run your account, perform the calculations you request on the data you provide, process your subscription, send service emails (sign-in links, receipts, account notices), keep the service secure, and meet our legal obligations.
We do not sell personal information. We do not use your fund data for advertising, and no analytics cookies are set.
Where your data lives
Your account and fund data are stored with Supabase in the Sydney, Australia region. We chose Australian-region hosting deliberately so fund data stays in Australia. All traffic is encrypted in transit (TLS). Some providers below process limited information outside Australia in the course of their function; where that happens we take reasonable steps to keep handling consistent with the Australian Privacy Principles.
Service providers
A small set of infrastructure providers run parts of the service. Each receives only what its function requires:
- Supabase: database and authentication (Sydney, Australia).
- Vercel: application hosting (global edge; functions in Sydney where configured).
- Stripe: payments and subscriptions, via Stripe Australia (PCI-DSS; we never see card numbers).
- Resend: transactional email such as sign-in links and receipts (United States).
- Anthropic: document-suggestion processing for statement text you upload or forward (United States; API data is not used for model training).
- Upstash: rate limiting, request metadata only (Sydney, Australia).
- Sentry: error monitoring; events pass a PII scrubber before leaving (United States).
- Plausible: cookie-free, aggregate-only analytics (European Union).
Retention, exports and deletion
We keep your information while your account is active and for any period the law requires afterwards. Your records are always exportable: BGL SF360, Class and CSV exports are available on every plan, during the trial, and after a subscription ends. You can ask us to delete your account and its data at hello@smsfcore.com; some records may be retained where the law requires.
Your rights
Under the Australian Privacy Principles you can ask us for access to the personal information we hold about you, ask us to correct it, or ask us to delete your account data. Email hello@smsfcore.com and we will respond within a reasonable time.
If you are not satisfied with our response to a privacy concern, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
If there is a data breach
If personal information we hold is lost, or accessed or disclosed without authorisation, we act on it straight away: we contain it, work out who is affected and what was involved, and record what happened.
If the breach is likely to result in serious harm to you and we cannot prevent that harm, we will tell you as soon as practicable: what happened, what information was involved, and what you can do about it. We will also notify the Office of the Australian Information Commissioner, following the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We keep a written record of every incident we assess, whether or not it needs notification. Questions about a suspected breach go to hello@smsfcore.com.
Changes
If this policy changes materially, we will email account holders and update the date at the top of this page.