GlobalPos Admin Portal

GlobalPos Bills

Privacy policy

Last updated: 25 September 2026

GlobalPos operates GlobalPos Bills and International Transfers within its internal staff portal to receive supplier documents and transfer confirmations, check purchase orders, prepare reviewed bills and record reviewed payments in Xero. This policy explains how those services handle personal information, including information received through Google APIs. It covers those two services, not every other GlobalPos website or staff workflow.

Information we collect

We collect documents uploaded by authorised staff and supplier emails imported from the connected office Gmail account. These can contain names, email and postal addresses, supplier contact details, invoice and purchase-order references, tax identifiers, payment details, descriptions and amounts.

We store the connected mailbox address, email identifiers, sender and subject, original imported emails and supported attachments, extracted document details, staff review notes, coding guidance and activity records. For International Transfers this includes confirmation message text, beneficiaries, currencies, exchange rates, fees, booking and invoice references, bill allocations and payment-recording results. Activity records identify staff actions and may contain document details. We also use supplier, account, tax, purchase-order, bill and payment records from the connected Xero organisation, and bank transactions from reconciliation reports uploaded to the portal.

Google provides access tokens and a refresh token so the service can check the mailbox without repeated sign-in. We do not receive or store the Google account password. Portal authentication and hosting services also process session and technical information needed to operate and protect the service.

Google account access

The Gmail connection requests read-only access using the gmail.readonly permission. This permission technically permits reading the connected mailbox. The portal limits its import searches to messages addressed or delivered to the designated bills address shown in Email setup. That address filter is an application control, not a restriction imposed by Google on the permission.

The integration does not send email, delete Gmail messages, change labels or mark messages as read. Original imported emails can include message-body content, signatures and attachments that are not invoices.

How we use information

We use this information to import and retain supplier documents, extract invoice and statement details, suggest accounting treatment, compare bills with purchase orders, identify possible duplicates and missing bills, support staff review, and create approved draft bills with attachments in Xero. We also use relevant records to investigate processing failures and maintain an audit history.

International Transfers reads TransferMate confirmation email bodies, groups confirmations by booking reference, and helps staff match foreign-currency payments and fees to supplier bills and imported bank withdrawals. Authorised staff can approve recording those payments and fees in Xero and review reconciliation evidence.

AI-generated details and coding suggestions require staff review. The service does not automatically approve supplier bills or transfer money. Recording an approved payment in Xero is an accounting action, not an instruction to a bank to send funds.

GlobalPos does not sell Google user data, use it for advertising or creditworthiness decisions, or use it to train a general-purpose AI model.

Service providers and AI processing

  • Google Gmail API: connects the authorised office mailbox and retrieves matching emails and attachments.
  • Google Gemini API: receives the document or TransferMate confirmation message text being read, together with extraction instructions and, where applicable, enabled supplier guidance, to return structured details. This includes PDF or image attachment contents and transfer confirmation email bodies, which may contain personal, banking or financial information.
  • Supabase: provides portal authentication, database storage and private document storage.
  • Vercel: hosts the portal and its server-side processing.
  • Xero: supplies accounting reference data and receives reviewed bill details and their supporting documents, or reviewed supplier payment and fee entries, when authorised staff submit them.

These providers process information to deliver their services under their applicable terms. Their infrastructure may process or store information outside Australia. This policy does not promise that all information remains in Australia.

Documents, email content, extraction prompts and AI responses must not be used to train or improve AI models. GlobalPos requires AI processing to use service terms and settings that prohibit this use, including by the AI provider. AI processing is limited to providing the document-reading features described in this policy. See the Gemini API terms.

Under Google’s paid Gemini API terms, prompts and responses may still be logged for a limited period to detect and prevent misuse and to meet legal or regulatory requirements. The no-training requirement does not mean that the provider retains no data.

Access and security

Access to Bills and International Transfers is restricted to authorised portal staff with the relevant permissions. GlobalPos staff and authorised service administrators may access information as needed for accounts processing, support, security and system administration. Gmail refresh tokens are encrypted before database storage, and document files are kept in private storage with access checks.

We use these controls to reduce unauthorised access. No online service can guarantee absolute security. Please send only information needed for the business purpose.

Retention and deletion

Imported documents and accounting records are retained for business, accounting, audit and applicable legal requirements. Bills and International Transfers do not currently apply a fixed automatic deletion period. Archiving a document retains it. Transfer confirmations, reviewed allocations and posting records are retained as evidence, including earlier confirmation versions.

Deleting a bill from the portal removes its bill record and attempts to remove its stored document file. A deletion audit record and the original imported email may remain; that original email may contain another copy of the attachment. Copies in Gmail, Xero and provider backups are not removed by deleting the portal bill. Contact us if you need a broader deletion request assessed, including associated emails and retained copies. Records may need to be retained where business or legal obligations require it.

Disconnecting Google

An authorised administrator can disconnect Gmail in Bills → Email setup. This removes the portal’s saved mailbox connection and refresh token and stops future mailbox checks through that connection. You can also revoke the app’s access in your Google Account connections.

Disconnecting does not delete previously imported information or stop processing documents already imported. Contact us separately about retention or deletion.

Google API data commitments

Our use of information received from Google APIs, including transfers to other services, is subject to the Google API Services User Data Policy and its Limited Use requirements. Google-derived information is used for the user-facing document and accounting features described here, rather than unrelated purposes.

Questions, corrections and requests

Contact GlobalPos at shane@globalpos.com.au to ask about this policy, request access to or correction of information, request deletion, or raise a privacy concern. We may need to verify your identity and authority before acting. We will explain any limitations on a request.

We may update this policy when the service or its data handling changes. The latest version and its update date will be available on this page.