Privacy Policy
Last updated: June 2026

How we look after
your data

This policy explains how Covalent API Pty Ltd (trading as Marbles) collects, uses, holds and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Contents
What we collect How we use it Who we share with Storage & security Your rights Cookies Contact us

What we collect

We collect information you provide directly when you create an account, connect a bank feed, import data from Xero or another provider, or contact us for support. This includes your name, email address, business name, ABN, and financial data you choose to store in Marbles.

We also collect limited technical data automatically: IP address, browser type, device information, and usage patterns within the product. This helps us improve the service and diagnose issues.

We do not collect sensitive personal information beyond what is necessary to provide the bookkeeping service - we are not an employer or healthcare provider and have no reason to hold information about your health, religion, or political views.

How we use it

Your data is used to provide and improve the Marbles service: reconciling and coding transactions, matching receipts and invoices, generating reports, preparing your BAS, and supporting the automated systems and Australian team that keep your books. We do not sell your data. We do not use your financial data to train AI models that are shared across customers without aggregation and anonymisation.

We may use your email address to send transactional notifications (BAS reminders, reconciliation summaries, security alerts) and, with your consent, product updates. You can opt out of marketing communications at any time.

Who we share with

We share data only with subprocessors necessary to deliver the service - cloud infrastructure (AWS Sydney), payment processing, and email delivery. A full subprocessor list is available on request. We do not share data with advertising networks, data brokers, or third parties for commercial purposes.

We will disclose data to government authorities where required by Australian law, including the ATO where you have authorised lodgement, and to the OAIC in the event of a notifiable data breach.

If you work with an accountant or bookkeeper who has access to your Marbles account, they will be able to see your financial data as part of that relationship. You control their access level through your account settings.

Storage & security

All data is stored in Australia on AWS Sydney infrastructure (ap-southeast-2). No personal or financial data is transferred outside Australia except to tightly scoped subprocessors, each reviewed and documented. Marbles is ISO 27001 certified.

We retain your data for the duration of your service and for 7 years following account closure, consistent with ATO record keeping requirements. You may request earlier deletion of non financial personal data (name, email, contact details) at any time.

Your rights

Under the Australian Privacy Principles, you have the right to access the personal information we hold about you, correct inaccurate information, and make a complaint if you believe we have mishandled your data. We will respond to access and correction requests within 30 days.

To exercise any of these rights, contact us at [email protected]. If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Cookies

We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how the product is used. We do not use third party advertising cookies. You can disable cookies in your browser but some product features will not work correctly without them.

Contact us

For privacy questions, data access requests, or complaints: [email protected]

Covalent API Pty Ltd · Sydney, Australia · ABN 65 652 751 598

This policy was last updated June 2026. We will notify active customers by email of any material changes before they take effect.