This policy says what hibiz stores and who can see it.

Last updated 3 October 2026.

hibiz is provided by [registered entity name and ABN to be confirmed]. This policy covers the public website and the app. It is written for the owner of a trades business and for the customers whose details that business enters.

hibiz stores what you enter to run your business.

For each business account hibiz stores:

  • the business name, ABN, GST registration, licence number, address, bank details and PayID you enter for your documents;
  • the name, email address and password hash of each user, and the role they hold;
  • customers and sites, with names, phone numbers, email addresses, addresses and access notes;
  • jobs, quotes, invoices, payments, notes, photos and the price list;
  • an activity log of who changed what and when, used to show the job timeline and, on Fleet, the business wide log;
  • a record of each AI assist run, with the time, which assist, how many tokens it used and whether it succeeded.

Passwords are stored as a salted hash and we cannot read them. If you add your own Anthropic API key it is encrypted before it is stored and is shown back to you masked.

Where your data is stored.

The database and the photos you upload are stored on [hosting region to be confirmed]. Backups are kept on the same server and in the same country. Where that is outside Australia, we take reasonable steps to make sure the hosting provider handles it to a standard comparable to the Australian Privacy Principles. The hibiz team can open your data to fix a problem you have reported and for no other reason.

hibiz uses one cookie to keep you signed in.

The app sets one cookie that holds your signed session. It is not used for advertising and it is not shared. The public website sets no cookies. We do not run third party analytics or advertising scripts on the website or in the app.

The AI assists send some fields to Anthropic, and only when a key is set up.

The four AI assists run only when an Anthropic API key has been configured, either on the server or by your business in settings. When you press one of the assist buttons, hibiz sends the following to Anthropic's API to produce a draft:

  • Draft quote lines: your site notes, your trade, your price list as a table of code, name, unit, ex GST price and kind, the customer's display name and the site suburb.
  • Write the work summary: the job title and description, the job notes in time order, photo captions, the quote line descriptions, the start and finish times and your trade.
  • Draft a customer message: the kind of message, the filled template, your business name, the customer's first name, the job title, the scheduled time, the quote or invoice number, total and due date, the days overdue, how many reminders have been sent and the delay in minutes. The quote and invoice links are replaced by a placeholder before the text is sent and put back afterwards, so the links themselves are never sent.
  • Fill a job from a pasted enquiry: the text you pasted, as typed, and the list of Australian state names. The pasted text is sent as it is, so it carries whatever the customer wrote, including their phone number or email address. Remove anything you do not want sent before you press the button.

Apart from what is in text you paste, hibiz never sends customer phone numbers, customer email addresses, bank details, your ABN or any API key to Anthropic. Anthropic's commercial API terms say that inputs and outputs sent through the API are not used to train its models. Each assist shows you the draft and nothing is saved or sent to a customer until you press the button to keep it. Without a key the buttons do not appear and nothing leaves the server.

Messages to customers go from your own phone or email.

hibiz does not send SMS or email to your customers. It writes the message and opens your phone's SMS or email app with it filled in, and the message goes from your own number or address. The emails hibiz sends itself are the invitation to a new user, the password reset link and a notice to the account owner when these terms or this policy change, through the mail server the business running hibiz has configured.

Customers of your business can open quotes and invoices by link.

A quote or invoice link contains a long random token and no login. Anyone with the link can read that document and, for a quote, accept or decline it. When a customer accepts a quote hibiz records the name they typed, the time and their IP address so you have a record of who agreed.

You can export or delete your data.

Every list in the app exports to CSV from the Export page, including while the account is read only. When a trial or a cancelled plan has been read only for 90 days the account and its data are deleted. To have an account deleted sooner, or to ask what we hold about you, use the contact form and we reply within one business day. If you are a customer of a business that uses hibiz and want your details changed or removed, ask that business, since they hold the account.

We follow the Australian Privacy Principles.

We handle personal information under the Privacy Act 1988 and the Australian Privacy Principles. If you think we have not, tell us through the contact form and we will respond within 30 days. You can also contact the Office of the Australian Information Commissioner. If we change this policy we will email the account owner and move the date at the top of this page.