Last updated 10 October 2026
Privacy policy
Nexoria is a customer portal for service businesses. This policy explains how we handle personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We don't sell personal information, we don't use it for advertising, and we don't use tracking or analytics cookies.
1. Who we are
Nexoria is operated by Riley William Loneragan trading as Nexoria (ABN 99 147 785 234), based in Queensland, Australia ("we", "us"). You can contact us about privacy at support@nexoria.com.au.
2. Our two roles
We handle personal information in two different capacities:
- For our own customers — the businesses that subscribe to Nexoria and the people who use it on their behalf ("account holders"). We decide how this information is used and this policy applies to it in full.
- On behalf of businesses — information a business stores about its customers (for example their name, contact details, vehicle or property details, quotes, invoices, messages and documents), and information those customers enter in the business's customer portal. The business is responsible for that information and decides how it is used; we store and process it only to provide the service to the business. If you are a customer of a business that uses Nexoria, please contact that business first about your information. We will help the business respond.
3. Information we collect
Account holders. Your name, email address and password (stored only as a one-way hash, never in readable form); two-factor authentication settings (the secret is encrypted); your role in each business; and your preferences.
Businesses. Business name, ABN, address, phone, email, website, logo and branding, opening hours, team members and plan. For billing we store the identifiers Stripe gives us and your subscription status. We never receive or store card numbers — Stripe handles them.
Information businesses store about their customers. Names, email addresses, phone numbers and addresses; details of vehicles, equipment or properties; jobs, quotes, invoices, payments, appointments and messages; and documents and photos the business or customer uploads.
Customer portal activity. When a customer signs in to a business's portal, accepts or declines a quote, or approves extra work, we record what happened, when, the name they typed (for acceptances), and their IP address and browser details. This is the evidence of what was agreed, for both the business and the customer.
Technical information. IP addresses and browser details for signed-in sessions, security monitoring and the audit log; and limited server logs. Rate-limiting records store only scrambled (hashed) identifiers and are deleted after 24 hours.
We collect information directly from you, from the business you work for or deal with, and automatically when the service is used.
4. How we use information
We use personal information only to:
- provide the service — workspaces, customer portals, quotes, jobs, invoices, bookings, messages and documents;
- send service emails: sign-in links, verification and password resets, quotes, invoices, receipts, reminders and notifications;
- process subscriptions and, where a business connects Stripe, its customers' invoice payments;
- keep accounts and data secure, prevent fraud and abuse, and investigate problems;
- provide support, and tell you about important changes to the service or these documents;
- meet legal obligations.
We don't send marketing emails to businesses' customers, and we don't use their information for our own purposes.
7. Overseas disclosure
Your data is stored in Australia. Some providers process information overseas to perform their service: Resend processes emails in Japan and may access them from the United States, and Stripe may process payment and billing information in the United States and other countries where it operates. We choose providers with strong security and privacy commitments.
8. How we protect it
- All connections use HTTPS encryption.
- Passwords are stored as strong one-way hashes; two-factor sign-in is available to everyone and required for our administrators.
- Each business's data is separated at the database level, so one business can never see another's.
- Uploaded files are private, scanned for malware before anyone can download them, and shared only through short-lived links.
- Customer portal sign-in uses single-use links that expire, instead of passwords.
- Access to our servers is restricted, and important actions are recorded in an audit log.
- We keep regular backups so data can be recovered.
No system is perfectly secure, but we work to protect your information and to respond quickly to any problem.
9. How long we keep it
- Active and read-only workspaces — kept so a business can continue or return. A business can delete individual records at any time.
- Closed workspaces — when an owner closes a workspace, everyone loses access immediately and all its data and files are permanently deleted after 30 days.
- Deleted user accounts — your name and email are removed and your password and two-factor settings are erased; records you created stay attributed to "Deleted user".
- Sign-in sessions expire after 30 days of inactivity; sign-in and reset links expire within hours (customer portal invitations after 7 days).
- Data exports are deleted 7 days after they are created.
- Backups are kept for 35 days, so deleted information can remain in backups until they expire.
Businesses are generally required to keep financial records (such as invoices) for 5 years. We don't delete invoices automatically, and we recommend exporting your data before closing a workspace.
10. Access and correction
Account holders can view and update their details in Account settings, delete their account there, and export a business's data from Settings → Data export. You can also ask us at support@nexoria.com.au.
Customers of a business should contact the business, which can update or archive their record and remove their portal access. If you can't reach the business, contact us and we'll help.
We respond to requests within 30 days and won't charge for making one.
11. Data breaches
If a data breach is likely to cause serious harm, we will notify the affected businesses and individuals and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme, and tell you what you can do to protect yourself.
12. Questions and complaints
Email support@nexoria.com.au. We'll acknowledge your complaint promptly and aim to resolve it within 30 days. If you're not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
13. Changes to this policy
We may update this policy as the service changes. We'll post the new version here with a new date, and email account holders about significant changes. See also our terms of service.