Privacy policy
Last updated: 26 June 2026
OnestopApprove is operated by Squirrelhog Pty Ltd (ABN 83 659 968 439) ("we", "us", "our"). This policy explains how we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using OnestopApprove you agree to this policy.
Who this policy covers
OnestopApprove is used by accounting and bookkeeping firms ("firms") to obtain client authorisations. It involves three kinds of people: firm users who send requests, client approvers who sign off, and the employees of those clients whose payroll information may appear in an attached report. We handle information about all three.
What we collect
- Account and identity: name and email address, managed through our authentication provider (Clerk). Passwords and any multi-factor details are held by Clerk, not by us.
- Approval records: the requests you create, the declarations agreed to, decisions (approve/decline), timestamps, and the audit trail of those events.
- Attachments: files you upload (such as payroll reports), which may contain employees' names and pay details. These are stored in a controlled, encrypted store and bound to an approval by a content hash.
- Usage and device data: basic technical information needed to operate and secure the service (for example request logs and a request identifier).
We do not store payment card numbers; subscription billing is handled by the app stores and our payment processor. We do not store sensitive identity documents in our application database.
How we use it
- To provide the service: create and deliver approval requests, record decisions, and produce audit exports.
- To keep the service secure and prevent misuse.
- To support you and respond to enquiries.
- To meet legal and record-keeping obligations (including retention of approval records).
We do not sell personal information, and we do not use it for advertising.
Storage and security
Data is hosted on Amazon Web Services in the Asia Pacific (Sydney) region. Attachments are encrypted at rest, access to them is logged, and approval records are append-only and tamper-evident. We apply access controls and least-privilege practices to limit who can reach personal information.
Who we share it with
We use a small number of trusted processors to run the service: Clerk (authentication), Amazon Web Services (hosting and email delivery), and our payment/subscription providers (such as the relevant app store, RevenueCat and Stripe). They process data on our instructions. We may also disclose information where required by law.
Retention
Approval records and their audit trail are retained for the period a firm needs to meet its compliance obligations (up to five years, consistent with ATO expectations), after which they may be deleted. Account information is retained while an account is active and removed (or de-identified) when no longer required.
Cross-border
Our primary hosting is in Australia. Some processors (for example authentication or payment providers) may process limited data overseas; where they do, we take reasonable steps to ensure appropriate protection.
Your rights
Under the APPs you can request access to, or correction of, the personal information we hold about you. If you are an employee of a client whose details appear in an attachment, the firm that uploaded it is the first point of contact, and we will assist them. To make a request or raise a privacy concern, contact us below. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
Cookies
This website uses only essential cookies. See our cookie policy for details.
Changes
We may update this policy from time to time. The "last updated" date above reflects the current version.
Contact
Squirrelhog Pty Ltd, support@onestopapprove.com.au, Sydney, Australia.