Astra CRM
  • Home
  • Request Info & Access

Astra CRM Privacy Policy

Last updated: 17 August 2026

1. Who we are

This Privacy Policy explains how Astra CRM Pty Ltd, ABN 34 074 841 062 (“Astra CRM”, “we”, “us”, “our”) collects, uses, discloses, and protects personal information in connection with the Astra CRM platform available at astracrm.com (the “Service”).

Astra CRM is a multi-tenant business management application. If you are an individual user accessing the Service on behalf of a business that has subscribed to Astra CRM (a “Tenant”), your use of the Service is also governed by any agreement between us and that Tenant, and by this Policy.

Astra CRM Pty Ltd is an Australian company, and we are committed to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), in addition to the US-specific commitments in Section 13 and Canada-specific commitments in Section 14 below. Contact details for our Privacy Officer are at the end of this Policy.

2. Scope of this Policy

This Policy applies to:

  • personal information we collect when a Tenant registers for and uses the Service;
  • personal information about individual users within a Tenant (staff, contacts, customers of the Tenant) that a Tenant stores in the Service;
  • personal information we receive through integrations with third-party accounting platforms, including Xero and QuickBooks Online (Intuit), where a Tenant has authorised such a connection; and
  • information collected through our website, astracrm.com.

Where a Tenant uploads or syncs personal information about its own customers, employees, or contacts into Astra CRM, the Tenant is generally the entity responsible for that information under privacy law (as the collector), and Astra CRM acts as a service provider processing that data on the Tenant’s behalf, in accordance with our agreement with the Tenant. Where this Policy refers to “you,” it refers to whichever of these categories applies to your use of the Service.

3. Information we collect

3.1 Account and registration information

Name, business name, email address, phone number, billing address, and login credentials for Tenant administrators and users.

3.2 Tenant business data

Business records that a Tenant enters, uploads, or syncs into Astra CRM in the course of using the Service — for example customer records, contacts, invoices, quotes, jobs, and notes. This may include personal information about the Tenant’s own customers or staff, which the Tenant is responsible for having the appropriate consent to provide to us.

3.3 Information from connected accounting platforms (Xero and QuickBooks Online)

If a Tenant chooses to connect Astra CRM to their Xero or QuickBooks Online (Intuit) account, we access data from that platform via the relevant provider’s API using an authorisation (OAuth2) token that the Tenant grants and controls.

We deliberately limit the scope of data we request to what our integration features need: customer/contact records, product/item records, and invoices (“Connected Platform Data”). We do not request or store general ledger transactions, journal entries, profit-and-loss or balance sheet reports, bank feed data, or banking/payment credentials from any connected platform. If this scope changes in the future (for example, if we add a payments-reconciliation feature that requires additional data), we will update this Policy and seek any additional authorisation required.

Xero and QuickBooks Online integration terms specific to United States and Canadian Tenants are set out in Sections 13 and 14 below.

3.4 Technical and usage data

IP address, device and browser type, log data, and usage statistics collected automatically when you use the Service or visit our website.

3.5 Multi-tenant identifiers

To keep each Tenant’s data securely separated, our platform associates data with a tenant identifier, a user identifier, and a data-centre identifier that determines where that Tenant’s data is physically hosted. These identifiers are technical/operational data and are not shared between Tenants.

4. How we use information

We use the information described above to:

  • provide, operate, and maintain the Service, including keeping each Tenant’s data logically separated from other Tenants;
  • authenticate users and enforce access controls;
  • provide the specific integration features a Tenant has connected (e.g., syncing invoices between Astra CRM and Xero);
  • provide customer support and respond to enquiries;
  • send Tenants and users service-related communications (e.g., security notices, service updates);
  • with consent, send marketing communications, which you may opt out of at any time;
  • improve, secure, and troubleshoot the Service; and
  • comply with our legal obligations, including obligations we owe to Xero and Intuit (QuickBooks Online) as platform providers.

5. Our commitments regarding Xero and QuickBooks Online data

Where Astra CRM accesses data through the Xero API or the Intuit (QuickBooks Online) API, we make the following specific commitments, reflecting the obligations imposed on us as an accredited App Partner/Developer Partner with each of these platforms:

  • We do not use Connected Platform Data to train, fine-tune, or otherwise develop any artificial intelligence or machine learning model. This applies to data obtained from Xero and QuickBooks Online in particular — each of which separately prohibits their developer partners from using platform data for AI/ML training without authorisation — and more broadly we do not use Tenant business data to train general-purpose or third-party AI models without separate, explicit consent.
  • We do not sell Connected Platform Data to any third party.
  • We do not pass on or aggregate Connected Platform Data to other apps or third parties, except where necessary to provide the integration the Tenant has requested, where the Tenant has separately consented, or where required by law.
  • We only access the data scopes necessary for the features a Tenant has actively enabled — in practice, customer/contact, product/item, and invoice records only, as described in Section 3.3 — and a Tenant may disconnect the integration (revoking our access) at any time from within the Service or directly through their Xero or QuickBooks Online account settings.
  • We maintain security controls consistent with Xero’s and Intuit’s respective developer security requirements, including encrypted transmission and storage of tokens and data, and multi-factor authentication for administrative access.
  • Data residency: Connected Platform Data obtained via Xero or QuickBooks Online is stored on our own infrastructure once retrieved (it is not left with the source platform), in the data centre region assigned to the relevant Tenant based on that Tenant’s home market: for United States and Canada Tenants (planned for our North American launch), that customer data will be hosted in the United States on AWS. See Section 7 for further detail.
  • Once data is disconnected or a Tenant’s subscription ends, we handle deletion of Connected Platform Data in accordance with Section 9 (Data retention and deletion) below.

Your use of Xero or QuickBooks Online remains subject to that provider’s own terms of use and privacy policies, which you should also review. Connecting Astra CRM to Xero or QuickBooks Online does not change your obligations to those providers.

6. How we disclose information

We do not sell personal information. We may disclose information to:

  • Sub-processors and service providers who help us run the Service (e.g., cloud hosting/data centre providers, email delivery, payment processing), under contractual obligations to protect the information and use it only for the purposes we specify;
  • Xero and Intuit (QuickBooks Online), to the extent necessary to operate an integration the Tenant has authorised;
  • Professional advisers (lawyers, accountants, auditors) where reasonably necessary;
  • Regulators, courts, or law enforcement, where required or authorised by law; and
  • A purchaser or prospective purchaser of our business or assets, subject to confidentiality obligations, in the event of a merger, acquisition, or sale.

A current list of our key sub-processors is available on request from our Privacy Officer.

7. Where your data is stored

Astra CRM operates a multi-tenant, multi-datacentre architecture. Each Tenant’s business data (including contacts, companies, activities, and Connected Platform Data synced from accounting integrations) is hosted in a specific data centre, identified internally by a data-centre identifier, determined by that Tenant’s home market:

  • United States and Canada Tenants: from the launch of Astra CRM in the North American market, customer data will be hosted in the United States on AWS.

This applies equally to Connected Platform Data obtained through Xero and QuickBooks Online integrations — a US or Canadian Tenant’s data will be hosted in the United States on AWS once that market launches. We do not move a Tenant’s data between regions except as necessary to support that Tenant’s own change of home market, with notice.

The Astra CRM web application interface may be delivered via a content delivery network for performance; that delivery layer does not change where your Tenant business data is stored.

Because Xero and Intuit are themselves international businesses, and because our infrastructure and sub-processors may involve entities based outside your country, some limited cross-border handling of data may still occur (for example, during authentication or support). For US/Canadian Tenants, we will take reasonable steps consistent with applicable US and Canadian privacy laws once that region launches.

8. Security

We use industry-standard technical and organisational measures to protect personal information, including:

  • encryption of data in transit (TLS) and at rest;
  • JSON Web Token (JWT)–based authentication, with tokens scoped to a specific tenant, user, and data centre;
  • role-based access controls restricting Astra CRM personnel access to Tenant data on a need-to-know basis;
  • multi-factor authentication for administrative and developer access to production systems; and
  • regular security review of our integrations with Xero and QuickBooks Online, consistent with each provider’s respective security requirements for developer partners.

No method of transmission or storage is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals as required by law, and will notify Xero and/or Intuit where the breach involves their respective Connected Platform Data, consistent with our obligations to them.

9. Data retention and deletion

We retain personal information for as long as needed to provide the Service to the relevant Tenant, and afterwards for as long as necessary to comply with our legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. When a Tenant closes its account or disconnects a Xero or QuickBooks Online integration, we will delete or de-identify the corresponding data within [X days], except where we are required to retain it by law or for legitimate business purposes (such as financial records).

10. Your rights

Subject to some exceptions under applicable law, you may:

  • request access to the personal information we hold about you;
  • request correction of inaccurate or out-of-date information;
  • opt out of receiving marketing communications at any time; and
  • make a complaint about how we have handled your personal information.

To exercise these rights, contact our Privacy Officer using the details below.

If you are an individual whose information has been entered into Astra CRM by a Tenant (for example, as one of that Tenant’s customers or contacts), you should generally direct access and correction requests to that Tenant in the first instance, as they control that data; we will assist the Tenant to respond where required.

11. Cookies and website analytics

Our website, astracrm.com, uses cookies and similar technologies for essential site functionality, analytics, and (where you consent) marketing purposes. You can control cookies through your browser settings. [Add detail here once your analytics/marketing stack is finalised, e.g. Google Analytics, and add a cookie consent banner if you use non-essential cookies.]

12. Children’s privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.

13. Additional terms for United States Tenants (including California Privacy Rights)

This section applies once the Service is offered to Tenants operating in the United States, in addition to (not instead of) the rest of this Policy.

13.1 Two roles we play. Like most SaaS providers, we act in two different capacities depending on whose data it is:

  • As a business, for our own data. When you (or your staff) give us your own contact details — for example, to sign up, request a demo, or subscribe to updates from us — we decide how that information is used, and California residents have the rights described in Section 13.3 in relation to it.
  • As a service provider, for your Tenant data. For the business data you store in Astra CRM, and for Connected Platform Data synced from Xero or QuickBooks Online, we act only on your instructions as your service provider — we are not deciding independently what to do with it. If one of your customers or contacts wants to exercise a privacy right over information you hold about them in Astra CRM, they should generally approach you (the Tenant) directly, and we will assist you in responding.

13.2 What we don’t do. We do not sell personal information, and we do not “share” it (in the CCPA/CPRA sense of sharing for cross-context behavioural advertising) with anyone. Because of this, the right to opt out of sale or sharing, while listed below for completeness, has nothing to opt out of under our current practices. We also do not collect Sensitive Personal Information (as CPRA defines it) beyond what is inherent in ordinary business records (e.g., we don’t collect health, biometric, or precise geolocation data); if that changes, we will update this Policy.

13.3 Your California/US rights. If you are a California resident (or a resident of a US state with a comparable privacy law), you may have the right to:

  • know/access — request that we disclose the personal information we have collected about you and how we’ve used it;
  • delete — request deletion of personal information we hold about you, subject to legal exceptions (e.g., where we must keep records for tax or legal reasons);
  • correct — request correction of inaccurate personal information;
  • opt out of sale or sharing — as noted above, we don’t currently sell or share personal information, so there is nothing to opt out of; and
  • non-discrimination — you won’t be denied service, charged a different price, or given a different level of service for exercising any of these rights.

You may make these requests by emailing our Privacy Officer at the address in Section 16. You may designate an authorised agent to make a request on your behalf; we may ask both you and the agent to verify your identity before acting on it. We may ask you to make no more than two verified requests of the same type within a 12-month period.

13.4 Our commitments as your service provider. Where we process Tenant data (including Connected Platform Data from Xero or QuickBooks Online) as your service provider, we commit to:

  • using it only to provide the Service and for the specific business purposes you’ve engaged us for, and not combining it with information from other sources to build profiles about your customers except as needed to run the Service;
  • not retaining, using, or disclosing it for any purpose outside our relationship with you, including not using it for our own independent business purposes; and
  • notifying you if we determine we can no longer meet our obligations as a service provider under applicable US privacy law.

13.5 QuickBooks Online (US). Our QuickBooks Online integration is administered through Intuit’s United States developer organisation. Data obtained via that integration for US Tenants is hosted in the United States on AWS (see Section 7), and is subject to the same data-minimisation and AI-training restrictions described in Section 5, in addition to Intuit’s own developer terms.

13.6 Other US state laws. Similar comprehensive privacy laws exist in a growing number of other US states (for example Virginia, Colorado, Connecticut, and Texas). The commitments in this section are intended to reflect the common core of these laws; if you are a resident of one of these states, the same rights and contact process described above apply to you.

14. Additional terms for Canadian Tenants

This section applies once the Service is offered to Tenants operating in Canada, in addition to (not instead of) the rest of this Policy. It reflects a good-faith summary of PIPEDA’s core principles rather than a full compliance program; Canada’s privacy regime is more fragmented than Australia’s (Quebec’s Law 25 in particular imposes stricter obligations than the federal baseline), so this section is worth a proper review with Canadian counsel before launch, though it doesn’t need to hold up publishing this Policy now.

We intend to handle personal information relating to Canadian Tenants and their contacts consistent with the ten fair information principles under the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial private-sector privacy legislation, including: obtaining appropriate consent for collection, use, and disclosure; limiting collection and use to identified purposes; providing individuals with access to their own personal information on request; and notifying the Office of the Privacy Commissioner of Canada and affected individuals of any breach of security safeguards involving personal information where required. Data obtained via our Canadian Tenants’ integrations (including QuickBooks Online) will be hosted in the United States on AWS alongside our US Tenants (see Section 7) unless and until we establish a dedicated Canadian data centre region; if that is a concern for your organisation, please contact us before connecting a Canadian account.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version on this page with a revised “Last updated” date, and where changes are material, we will notify Tenants by email or in-app notice.

16. Contact us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact:

support@astracrm.com.au


This Privacy Policy should be read together with our Terms of Use.

© 2026 Astra CRM. All rights reserved.
Privacy PolicyTerms of Use